Security by design
Avendo applies layered controls designed to protect confidentiality, integrity, and availability. Controls are reviewed as the product, risks, and infrastructure change.
Core practices
- Encrypted transport for supported production connections.
- Role-aware access and least-privilege operational access.
- Authentication, session protection, and audit-oriented event logging.
- Dependency, infrastructure, and application security maintenance.
- Backup and recovery processes appropriate to the service tier.
- Incident assessment and notification processes aligned with contractual and legal requirements.
Customer responsibility
Customers should protect credentials, configure roles carefully, review connected-platform permissions, validate generated content before publishing, and promptly remove access for users who no longer need it.
Report a vulnerability
Please report suspected vulnerabilities privately with reproduction steps and potential impact. Do not access other users' data, disrupt the service, or publicly disclose an unresolved issue.
Report a security issue